
@sudheerdotai Good catch. Two in the same batch, CVE-2026-104334 and CVE-2026-93674, score 9.8 and need no login at all. Same fix for the whole set: 1.12.3 or newer, and keep Langflow off the open internet until it's patched.
Signal is active with 3 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

@sudheerdotai Good catch. Two in the same batch, CVE-2026-104334 and CVE-2026-93674, score 9.8 and need no login at all. Same fix for the whole set: 1.12.3 or newer, and keep Langflow off the open internet until it's patched.

CVE-2026-93674 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. https://www.cve.org/CVERecord?id=CVE-2026-93674

IBM Langflow OSS に認証不要で任意コードを実行される OS コマンドインジェクション(CVE-2026-93674・CVSS 9.8)。1.0.0〜1.12.2 が対象で、1.12.3 で修正。回避策は無いので、使っている環境は版を確認して更新を。 https://cve.autoarticles.net/cve/CVE-2026-93674

🚨 Critical Langflow OSS OS Command Injection Enables Unauthenticated Remote Code Execution Critical Vulnerability Alert! Langflow OSS is affected by CVE-2026-93674. 🔍 Identify Targets via ZoomEye: Search Dork: app="Langflow" Exposure: 18.8k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJMYW5nZmxvdyI%3D #Infosec #CyberSecurity #ZoomEye